Назад
Company hidden
12 часов Π½Π°Π·Π°Π΄

Security Control Assessor (Cybersecurity)

60Β 000 - 180Β 000$
Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
onsite
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
senior
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
US
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Security Control Assessor (Cybersecurity): Planning and executing security control assessments for federal information systems under NIST RMF Steps 0–7 with an accent on control effectiveness, vulnerability analysis, and authorization documentation. Focus on developing assessment procedures, preparing Security Assessment Reports, validating remediation actions, and conducting continuous monitoring for systems requiring Secret clearance.

Location: On-site in Alexandria, Virginia, United States; active Secret security clearance required

Salary: $60,000–$180,000 USD per year

Company

hirify.global provides IT services and cybersecurity solutions to the Federal Government and commercial customers, including security, cloud migration, software development, analytics, and infrastructure services.

What you will do

  • Plan and execute security control assessments for information systems across Risk Management Framework Steps 0–7.
  • Develop assessment procedures and methodologies aligned with NIST guidance and relevant security frameworks.
  • Analyze control effectiveness, identify vulnerabilities and weaknesses, and validate control implementation through testing.
  • Prepare Security Assessment Reports with findings and recommendations.
  • Collaborate with system owners, ISSOs, and stakeholders during authorization activities.
  • Verify remediation actions, support System Security Plans and POA&Ms, and perform follow-up assessments and continuous monitoring.

Requirements

  • Active Secret security clearance required.
  • Bachelor’s degree or equivalent relevant experience, plus 5+ years of relevant experience.
  • One of the following certifications: CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, or SSCP.
  • Strong knowledge of NIST RMF implementation guidance and vulnerability management practices.
  • Hands-on experience with eMASS or similar Information Assurance tools.
  • Experience analyzing vulnerability scans, assessing STIG implementations, conducting RMF Step 4 assessments, and performing continuous monitoring.

Culture & Benefits

  • Full-time employee position with a competitive compensation package.
  • Benefits are provided as part of the employee package.
  • Work supports Federal Government programs and cybersecurity modernization initiatives.
  • Company values diverse perspectives and supports veterans, transitioning service members, military spouses, and dependents.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’